Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Nexpose MEDIUM 5.3
CVE-2019-5640

Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an a…

Fix: 6.6.114+
Fix from $1,600 2021-11-22
Ozone MEDIUM 5.3
CVE-2021-41532

In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any unauthenticated user can access…

Fix: 1.2.0+
Fix from $1,600 2021-11-19
Command Centre MEDIUM 6.5
CVE-2021-23193

Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unprivileged operators to retrie…

Fix: 8.20.1291 / 8.30.1454+
Fix from $1,600 2021-11-18
Metabase HIGH 7.5
CVE-2021-41277 KEVEPSS 97%

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->se…

Patch available
Fix from $1,950 2021-11-17
Discourse MEDIUM 5.3
CVE-2021-41271

Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an error response to be cached by in…

Fix: after 2.7.9
Fix from $1,600 2021-11-15
Rails Multisite HIGH 8.8
CVE-2021-41263

rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Rails applications using `rails…

Fix: 4.0.0+
Fix from $1,950 2021-11-15
Apq8009 Firmware CRITICAL 9.1
CVE-2021-30284

Possible information exposure and denial of service due to NAS not dropping messages when integrity check fails in Snapdragon Auto, Snapdragon Comput…

Mitigation only
Fix from $2,300 2021-11-12
Cloud Sdk MEDIUM 5.9
CVE-2021-41251

@sap-cloud-sdk/core contains the core functionality of the SAP Cloud SDK as well as the SAP Business Technology Platform abstractions. This affects a…

Fix: 1.52.0+
Fix from $1,600 2021-11-05
GitLab MEDIUM 5.3
CVE-2021-39898

In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project whi…

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-11-05
Spring Cloud Openfeign HIGH 7.5
CVE-2021-22044

In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapp…

Fix: after 3.0.4
Fix from $1,950 2021-10-28
Spring Data Rest MEDIUM 5.3
CVE-2021-22047

In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a …

Fix: after 3.5.5
Fix from $1,600 2021-10-28
Freeswitch HIGH 7.5
CVE-2021-41158

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…

Fix: 1.10.7+
Fix from $1,950 2021-10-26
Richdocuments MEDIUM 5.3
CVE-2021-39223

Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Richdocuments application prior to versions 3.8.6 and 4.2.3 returned ve…

Fix: 3.8.6 / 4.2.3+
Fix from $1,600 2021-10-25
Officeonline MEDIUM 5.3
CVE-2021-39224

Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud OfficeOnline application prior to version 1.1.1 returned verbatim excep…

Fix: 1.1.1+
Fix from $1,600 2021-10-25
Ingepac Da Au Firmware MEDIUM 5.3
CVE-2017-20007

Ingeteam INGEPAC DA AU AUC_1.13.0.28 (and before) web application allows access to a certain path that contains sensitive information that could be u…

Mitigation only
Fix from $1,600 2021-10-25
Wireless 1410 Gateway Firmware MEDIUM 6.5
CVE-2021-42536

The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables.

Fix: 4.7.94+
Fix from $1,600 2021-10-22
Session And Resource Control MEDIUM 5.3
CVE-2021-31380

A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a special…

Fix: 4.12.0r5 / 4.13.0r3+
Fix from $1,600 2021-10-19
Session And Resource Control CRITICAL 9.1
CVE-2021-31381

A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a special…

Fix: 4.12.0r5 / 4.13.0r3+
Fix from $2,300 2021-10-19
Junos MEDIUM 5.3
CVE-2021-31371

Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing t…

Fix: after 17.2
Fix from $1,600 2021-10-19
Session And Resource Control MEDIUM 5.3
CVE-2021-31352

An Information Exposure vulnerability in Juniper Networks SRC Series devices configured for NETCONF over SSH permits the negotiation of weak ciphers,…

Fix: 4.130r6+
Fix from $1,600 2021-10-19
Discourse Reactions MEDIUM 5.3
CVE-2021-41140

Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given …

Fix: 0.2+
Fix from $1,600 2021-10-19
Vrealize Automation MEDIUM 6.5
CVE-2021-22036

VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able…

Fix: 8.6+
Fix from $1,600 2021-10-13
Inbody MEDIUM 5.3
CVE-2021-20832

InBody App for iOS versions prior to 2.3.30 and InBody App for Android versions prior to 2.2.90(510) contain a vulnerability which may lead to inform…

Fix: 2.2.90 / 2.3.30+
Fix from $1,600 2021-10-13
Sinec Nms MEDIUM 6.5
CVE-2021-33727

A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could download the user profile of any…

Fix: 1.0+
Fix from $1,600 2021-10-12
PostgreSQL MEDIUM 6.5
CVE-2021-32028

A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an authenticated database user coul…

Fix: 9.6.22 / 10.17+
Fix from $1,600 2021-10-11
PostgreSQL MEDIUM 6.5
CVE-2021-32029

A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary…

Fix: 11.12 / 12.7+
Fix from $1,600 2021-10-08
Zammad HIGH 7.5
CVE-2021-42089

An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.

Fix: 4.1.1+
Fix from $1,950 2021-10-07
Debian Linux MEDIUM 6.5
CVE-2021-41125

Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider a…

Fix: 1.8.1 / 2.5.1+
Fix from $1,600 2021-10-06
Android MEDIUM 5.5
CVE-2021-0644

In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permiss…

Patch available
Fix from $1,600 2021-10-06
Paypal HIGH 7.5
CVE-2021-41120

sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was…

Fix: 1.2.4 / 1.3.1+
Fix from $1,950 2021-10-05